https://seclists.org/oss-sec/2025/q4/292: [Advisory] WebKit/iOS 26.2: Gigacage Boundary Violation via Logic Flaw enabling OOB Access
Published Dec 26, 2025
·Updated
Affected Software
2 affected components
Apple iOS
Apple WebKit
Frequently Asked Questions
1
What is the severity of CVE Pending related to WebKit/iOS 26.2?
The severity of CVE Pending for WebKit/iOS 26.2 is currently under assessment but indicates a significant security risk due to the Gigacage boundary violation.
2
How do I fix CVE Pending in WebKit/iOS 26.2?
To fix CVE Pending in WebKit/iOS 26.2, upgrade to the latest version of iOS provided by Apple once the patch is released.
3
What is the Gigacage boundary violation vulnerability in WebKit/iOS 26.2?
The Gigacage boundary violation vulnerability in WebKit/iOS 26.2 is a logic flaw leading to out-of-bounds access due to an integer overflow.
4
Who is affected by the CVE Pending vulnerability in WebKit/iOS 26.2?
Users of Apple iOS 26.2 using WebKit are affected by the CVE Pending vulnerability.
5
What are the potential consequences of the Gigacage boundary violation in WebKit/iOS 26.2?
The potential consequences of the Gigacage boundary violation include unauthorized access to sensitive data and exploitation of system memory.